Vulnerabilities > Jetbrains
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-02-06 | CVE-2024-24938 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation | 5.3 |
2024-02-06 | CVE-2024-24939 | Information Exposure Through Log Files vulnerability in Jetbrains Rider In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible | 5.3 |
2024-02-06 | CVE-2024-24940 | Path Traversal vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives | 4.3 |
2024-02-06 | CVE-2024-24941 | Improper Input Validation vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL | 5.3 |
2024-02-06 | CVE-2024-24942 | Path Traversal vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | 5.3 |
2024-02-06 | CVE-2024-24943 | Resource Exhaustion vulnerability in Jetbrains Toolbox In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image | 5.5 |
2024-01-09 | CVE-2024-22370 | Cross-site Scripting vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible | 5.4 |
2023-12-21 | CVE-2023-51655 | Insufficient Verification of Data Authenticity vulnerability in Jetbrains Intellij Idea In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration | 9.8 |
2023-12-15 | CVE-2023-50870 | Cross-Site Request Forgery (CSRF) vulnerability in Jetbrains Teamcity In JetBrains TeamCity before 2023.11.1 a CSRF on login was possible | 8.8 |
2023-12-15 | CVE-2023-50871 | Unspecified vulnerability in Jetbrains Youtrack In JetBrains YouTrack before 2023.3.22268 authorization check for inline comments inside thread replies was missed | 4.3 |